SonicWall has released urgent security updates addressing four vulnerabilities affecting its SMA1000 series appliances. The security flaws range from server-side request forgery and remote code execution to Zip Slip and stored cross-site scripting, with the most serious vulnerability receiving the maximum CVSS 3.1 severity score of 10.0.
The affected appliances include the SonicWall SMA1000 models 6210, 7210 and 8200v running certain older software versions. SonicWall has not identified any evidence that the four vulnerabilities are currently being exploited in the wild, but administrators are strongly advised to update affected systems because no alternative workaround has been provided.
Four Vulnerabilities Affect The SMA1000 Series
The newly addressed security issues are tracked as CVE-2026-102255, CVE-2026-102256, CVE-2026-102257 and CVE-2026-102258. Their CVSS 3.1 scores range from 5.5 to the maximum rating of 10.0, covering vulnerabilities with Critical, High and Medium severity classifications.
The weaknesses affect different parts of the SMA1000 platform, including the Appliance Work Place interface and Appliance Management Console. Depending on the vulnerability, successful exploitation could allow an attacker to access internal functions, execute operating system commands or inject JavaScript into the management interface.
CVE-2026-102255 Receives Maximum 10.0 Severity Score
The most serious vulnerability is CVE-2026-102255, a pre-authentication server-side request forgery, or SSRF, flaw affecting the SMA1000 Appliance Work Place interface. It carries a Critical CVSS score of 10.0.
The vulnerability stems from an unintended alternate access path. A remote attacker who does not need to authenticate could potentially abuse the flaw to make the SMA1000 appliance send requests on the attacker's behalf.
This could allow access to internal functionality and enable unauthorised operations. Because authentication is not required, this vulnerability represents the most immediately concerning issue among the four flaws addressed in the update.
Why Pre-Authentication SSRF Is Particularly Concerning
Server-side request forgery vulnerabilities allow attackers to manipulate a vulnerable system into making network requests that would normally originate from the trusted server itself. Depending on the environment, this can give attackers access to services that are not directly exposed to the internet.
In the case of the SMA1000 vulnerability, the issue exists within an interface designed to provide appliance functionality. An attacker could potentially exploit the unintended access path remotely without first possessing valid administrator credentials.
The lack of an authentication requirement is one reason the vulnerability carries the maximum severity score.
CVE-2026-102256 Can Lead To Remote Code Execution
The second vulnerability, CVE-2026-102256, is an operating system command injection issue carrying a High CVSS score of 7.8. Unlike the SSRF vulnerability, exploitation requires the attacker to already be authenticated as an administrator.
The flaw is caused by improper neutralisation of special elements used within operating system commands. Under specific conditions, an authenticated administrator could potentially inject arbitrary commands into the affected SMA1000 appliance.
Successful exploitation could result in remote code execution, effectively allowing the attacker to execute commands at the operating system level.
CVE-2026-102257 Involves A Zip Slip Vulnerability
CVE-2026-102257 is another High-severity vulnerability, with a CVSS score of 7.2. The flaw affects the Appliance Management Console and involves a Zip Slip condition.
Under specific circumstances, a remote authenticated attacker with administrator privileges could exploit the vulnerability and ultimately execute arbitrary operating system commands on the appliance. As with CVE-2026-102256, successful exploitation could therefore result in remote code execution.
Although authentication and administrator privileges are required, vulnerabilities of this type remain important because compromised administrative credentials could allow an attacker to escalate the impact of an existing intrusion.
Stored XSS Vulnerability Also Affects The Management Console
The fourth vulnerability, CVE-2026-102258, affects the SMA1000 Appliance Management Console and is classified as Medium severity with a CVSS score of 5.5.
This issue is a stored cross-site scripting, or XSS, vulnerability. Under specific conditions, an authenticated attacker with administrator privileges could store and execute arbitrary JavaScript code within the Appliance Management Console.
Stored XSS can be particularly persistent because malicious content is saved within the affected application rather than requiring the attacker to deliver a specially crafted link every time. However, this specific vulnerability requires authenticated administrative access.
No Evidence Of Active Exploitation So Far
SonicWall has stated that it currently has no evidence indicating that any of these four vulnerabilities are being exploited in real-world attacks.
That is reassuring, particularly for organisations that can apply the security updates promptly. However, the absence of known exploitation does not eliminate the risk, especially now that the vulnerabilities and affected software versions are publicly identified.
Administrators responsible for SMA1000 appliances should therefore treat the update as preventative security work rather than waiting for reports of exploitation before responding.
SMA1000 Models 6210, 7210 And 8200v Are Affected
The vulnerabilities affect SonicWall SMA1000 models 6210, 7210 and 8200v running specific older software versions.
Affected installations include:
Organisations operating any of these appliances should verify the software version currently installed and determine whether an update is required.
Keeping an accurate inventory of security appliances is particularly important because remote-access infrastructure can sometimes remain in service for long periods without receiving the same attention as endpoint devices.
SonicWall Firewall SSL VPN And SMA 100 Series Are Not Affected
Importantly, the vulnerabilities do not affect SSL VPN functionality running on SonicWall firewalls.
The separate SonicWall SMA 100 Series product line is also not affected by these particular security issues. This distinction is useful for organisations operating multiple SonicWall products because the advisory specifically applies to the SMA1000 series rather than the company's entire VPN and remote-access portfolio.
Administrators should therefore confirm the exact product family and version before determining whether remediation is necessary.
Fixed Software Versions Are Already Available
SonicWall is strongly recommending that customers upgrade affected SMA1000 appliances to patched software versions.
For SMA1000 models 6210, 7210 and 8200v, the fixed releases are:
Administrators running older builds should therefore plan an upgrade to one of these versions or a later supported release.
There Is No Workaround Available
One of the most important details for administrators is that SonicWall has not provided a workaround for the vulnerabilities.
That means organisations cannot rely on an alternative configuration change or temporary mitigation instead of installing the security update. Upgrading to the fixed software versions remains the recommended way to address the affected systems.
This makes timely patching particularly important for organisations where SMA1000 appliances are exposed to external users or form part of critical remote-access infrastructure.
Administrators Should Verify Versions Rather Than Assume Systems Are Safe
Because the affected and fixed versions are separated by relatively specific platform hotfix numbers, administrators should verify the exact build installed on each appliance. Simply knowing that an environment is running version 12.4.3 or 12.5.0 is not enough to determine whether it is protected.
An SMA1000 appliance running 12.4.3-03526, for example, remains affected, while 12.4.3-03670 contains the required fixes. Similar attention is required for the 12.5.0 release branch.
For larger organisations operating multiple appliances, checking each device individually can help avoid situations where one overlooked system remains vulnerable after the rest of the environment has already been updated.
Final Thoughts
The four newly addressed SonicWall SMA1000 vulnerabilities should receive prompt attention from organisations using models 6210, 7210 or 8200v. The most serious issue, CVE-2026-102255, carries a maximum CVSS score of 10.0 and can potentially be exploited remotely without authentication through a server-side request forgery weakness.
The remaining vulnerabilities include two administrator-level issues capable of leading to remote code execution and a stored cross-site scripting flaw affecting the management console. Although SonicWall has not observed active exploitation so far, there is currently no workaround available. Administrators should therefore verify their software versions and upgrade affected appliances to 12.4.3-03670, 12.5.0-03082 or later supported builds as soon as practical.


Comments 0